[Git][security-tracker-team/security-tracker][master] 2 commits: lts: dogtag-pki postponed in bullseye

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Mon Jul 27 02:06:04 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
98933043 by Utkarsh Gupta at 2026-07-27T06:25:57+05:30
lts: dogtag-pki postponed in bullseye

- - - - -
b3e26ebb by Utkarsh Gupta at 2026-07-27T06:35:45+05:30
lts: python3.9 postponed in bullseye, align bookworm wording

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1876,6 +1876,7 @@ CVE-2026-17048 (A flaw was found in the Keycloak Admin REST API, which is used t
 	- keycloak <itp> (bug #1088287)
 CVE-2026-17039 (A flaw was found in pki-core. The certificate authority (CA) renewal r ...)
 	- dogtag-pki <removed>
+	[bullseye] - dogtag-pki <postponed> (Minor issue; missing checkRealm in RenewalProcessor, only reachable with non-default realm-mapped authz config; unfixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506720
 	NOTE: Fixed by: https://github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6
 CVE-2026-16910 (A flaw was found in Red Hat Quay's notification webhook feature. The S ...)
@@ -16469,8 +16470,9 @@ CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
-	[bookworm] - python3.11 <postponed> (CPU-only DoS; the quadratic rescan requires the incremental feed() API driven in chunks, a single feed() of the whole document stays linear; no upstream 3.11 fix released, backport PR gh-153042 still unmerged)
+	[bookworm] - python3.11 <postponed> (CPU-only DoS; the quadratic rescan needs feed() driven in small chunks, a single feed() of the whole document stays linear; no upstream fix for this branch)
 	- python3.9 <removed>
+	[bullseye] - python3.9 <postponed> (CPU-only DoS; the quadratic rescan needs feed() driven in small chunks, a single feed() of the whole document stays linear; no upstream fix for this branch)
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/
@@ -16479,6 +16481,11 @@ CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for
 	NOTE: https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd (v3.15.0b4)
 	NOTE: https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 (3.14 branch)
 	NOTE: https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced (3.13 branch)
+	NOTE: The CNA description ("repeated unterminated markup declarations") describes the
+	NOTE: CVE-2025-6069 corpus, not this issue: a single unterminated construct fed in small
+	NOTE: chunks is enough, and start tags and RAWTEXT elements such as <script> are affected
+	NOTE: too. Backports are still unmerged on every branch <= 3.12 (gh-153041/153042/153043);
+	NOTE: 3.9 has no backport PR and went EOL 2025-10-31, before the issue was filed.
 CVE-2026-15204 (A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515 ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-15202 (A security vulnerability has been detected in YzmCMS up to 7.5. Affect ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3e2702e0876ce08ca41d237f186fc1a27a52d6c4...b3e26ebb1624242ce6d59c56ac6d6fc8b78bfae0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3e2702e0876ce08ca41d237f186fc1a27a52d6c4...b3e26ebb1624242ce6d59c56ac6d6fc8b78bfae0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/82f3a398/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list